Legal · European by design

Privacy statement

How SpringFur collects, uses and protects personal data when you visit our website, contact us or use our services.

Version 1.0 · Effective 23 September 2026
Privacy by design. We aim to collect only what we need, keep it only as long as necessary and make processing understandable. This statement may be supplemented by a customer agreement or data processing agreement.

1. Who is responsible?

SpringFur is a product and service operated by HN7 B.V. (“SpringFur”, “we” or “us”). HN7 B.V. is the controller for personal data processed for our own business purposes. Where we process customer-submitted data solely on documented customer instructions, the customer is normally the controller and we act as processor.

Privacy questions may be sent to privacy@springfur.nl.

2. Personal data we process

Depending on your interaction with us, we may process:

  • name, business contact details, organisation and role;
  • account, authentication and access information;
  • communications, requests, agreements and support history;
  • technical logs such as IP address, browser, device, timestamps and security events;
  • usage information needed to operate, secure and improve the service;
  • billing and transaction administration;
  • content and metadata you deliberately submit for analysis, to the extent it contains personal data.

We do not intentionally request special-category personal data. Please do not submit such data unless this has been expressly agreed and appropriate safeguards are in place.

3. Purposes and legal grounds

We use personal data to provide and secure the service, manage accounts and agreements, respond to enquiries, comply with law, prevent abuse and improve SpringFur. Depending on the activity, we rely on performance of a contract, steps requested before a contract, compliance with a legal obligation, a legitimate interest that is not overridden by your rights, or consent where required. You may withdraw consent at any time without affecting earlier lawful processing.

4. Customer software and analysis data

Repositories, exported projects, architecture files and related evidence remain under the customer’s control. Customers must ensure they are authorised to submit this material and must avoid unnecessary personal data. We use submitted material only to provide, secure and support the agreed service, unless a separate written agreement permits another use.

Product arrangements may offer local, isolated or otherwise restricted analysis. The applicable order, security schedule and data processing agreement determine the actual deployment, subprocessors, locations and deletion commitments.

5. Recipients and international transfers

We may use vetted hosting, security, communications, analytics, payment and professional-service providers. They receive only the information reasonably necessary for their role and are bound by appropriate obligations. We may also disclose information where legally required or necessary to establish, exercise or defend legal claims.

If personal data is transferred outside the European Economic Area, we use an applicable legal transfer mechanism and supplementary safeguards where required. Current subprocessor information is available on request.

6. Retention

We retain personal data no longer than necessary for the stated purpose, contractual commitments, security, dispute handling and statutory administration. Retention periods depend on the data category and customer configuration. Submitted analysis content is deleted or returned according to the applicable agreement and service settings.

7. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. We may ask for information needed to verify your identity. Send requests to privacy@springfur.nl. You also have the right to lodge a complaint with the Dutch Data Protection Authority or another competent supervisory authority.

8. Security and incidents

We apply proportionate technical and organisational safeguards. No system can be guaranteed completely secure. If an incident creates notification obligations, we will act in accordance with applicable law and the relevant customer agreement.

9. Cookies and external links

The current public website does not intentionally use advertising cookies. Essential hosting and security functions may process technical request information. If analytics or other non-essential technologies are introduced, we will update this statement and request consent where required. External websites have their own privacy practices.

10. Changes and contact

We may update this statement when our service or legal obligations change. Material changes will be communicated through an appropriate channel. Questions can be sent to privacy@springfur.nl.